CVE-2016-0801 - dropping BRCM proprietary packets received over the air. CVE-2017-0561 - adding length checks for TDLS action frames. CVE-2017-9417 - adding length checks for WME IE. switch to using a tar.xz generated from a full checkout of linux-firmware; other ports packaging pieces of linux-firmware could be switched over to using the same file.